NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / New Zealand

Waikato DHB cyberattack: Board prewarned security was severely compromised

Natalie Akoorie
By Natalie Akoorie
Local Democracy Editor·Other·
11 Nov, 2021 08:17 PM6 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

4200 people were affected by the breach. Photo / 123RF

4200 people were affected by the breach. Photo / 123RF

The Waikato District Health Board was warned its IT security was inadequate and severely compromised just months before a massive ransomware attack that brought Waikato Hospital to its knees.

An internal cyber security document dated December last year also warned that a lack of training meant staff posed an unintentional threat to its systems.

However, Waikato DHB said the strategy was only a draft that was part of a wider digital strategy about to be heard by the DHB's commissioners when hackers struck on May 18.

The draft strategy, seen by Local Democracy Reporting, says the DHB's IT security was compromised by outdated systems, infrastructure and staff resourcing, making it a sitting duck for a major cybersecurity attack.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

In the aftermath of the cyberattack, some cancer patients were transferred and elective surgeries postponed as hackers brought down hundreds of servers and patient and staff information was dumped on the dark web.

The strategy said at the time there was no cyber security incident response plan and noted the urgent incident response option available to staff at Waikato Hospital was to "unplug network equipment".

It appears to be a damning indictment of the state of IT security at the DHB five months before the cyber security breach.

The 32-page report said Waikato DHB:

Advertisement
Advertise with NZME.

* Was still using Windows XP on some systems, a software released in 2001 that has been unsupported for five years;

* Relied on "perimeter security" such as firewalls, blocking, and malware protection that was becoming outdated as the DHB moved to cloud-based services;

* Struggled with multiple IT applications with inconsistent functionality, most very old and with poor support if any;

* Was behind on patching, the installation of critical software updates for security purposes;

Discover more

New Zealand

Live: Taranaki Covid cases 'very reluctant' to get tested, were not using tracer app

11 Nov 07:45 PM
Business

Mother's illness inspired cutting-edge health devices

11 Nov 04:00 PM
Business

Amal Clooney calls for business to play their part in stopping human rights abuse

10 Nov 09:51 PM
New Zealand

Covid-19: Why Govt is rethinking contact tracing

11 Nov 04:45 AM

* Did not have enough IT staff to manage and co-ordinate IT security with no cyber security specialist, and investments in cyber security were not prioritised;

* Did not have continuously monitored cloud services to detect suspicious behaviour;

* And did not have appropriate policies or training for staff around IT security.

The strategy, authored by two DHB employees, estimated the DHB had at least 800 software applications, many of them known to be duplicating significant functionality.

"Some of the legacy systems do not have security setups that can be modernised to protect against current security threats, and the majority are based on technology that is so old that it can no longer be patched or updated to guard against emerging security threats."

There was no procurement policy designed to monitor and regulate the purchase of medical devices used in patient care.

Advertisement
Advertise with NZME.

This meant they were often bought based on vendor demonstrations without consideration of compatibility.

"As a result, the DHB has many systems and devices that were acquired to perform a clinical role but which have many security holes that are difficult to plug."

The strategy gave an example of clinical devices connectable to the internet that were running Windows XP.

"These old control systems cannot be patched, and when the machines are plugged into the network they pose significant risk to the DHB's network and other devices."

The devices had poorly configured IT security controls that could be compromised by malware, resulting in bad readings, corrupted data, or even being hacked for patient data.

"This creates clinical risk for patients and for the DHB."

Advertisement
Advertise with NZME.

There was also no "follow-you" printing model at the DHB, meaning unauthorised parties could potentially view printed information at the printer.

The document said a skills deficit in the IT unit meant the DHB's IT operations approach was to reduce cyber risk by locking systems down and limiting access.

"DHB clinical staff have responded to this by turning to 'shadow IT' – informal software applications and personal hardware devices – which in turn increases IT risk even more, creating a never-ending risk cycle that gets worse with every turn."

With a limited budget, Waikato DHB was faced with a difficult choice when allocating resources, the report said, and cyber security had not been a priority when the DHB was struggling to meet minimum requirements for IT provision to support the delivery of healthcare.

"This trade-off is a common one at the DHB, even though the consequences of a targeted cyberattack would be catastrophic for patient safety."

Sources told Local Democracy Reporting the draft strategy was abandoned because of cost but Waikato DHB chief executive Dr Kevin Snee said: "This was a working document that was an input into the broader Digital Health Strategy that subsequently came to the executive on May 13."

Advertisement
Advertise with NZME.

"It proposed substantial investment into digital technology, was supported by the executive, and was due to go to the commissioners on May 26 but was interrupted by the cyberattack."

A DHB spokesperson said the work had been initiated by the DHB's new digital leadership to address any areas that required attention, and support the migration to new solutions such as cloud-based applications, which would also introduce new cyber security considerations as it moved systems outside the "perimeter security" setting of firewalls, intrusion and malware protections.

"The document had not yet reached final draft, had not been reviewed or qualified and had not been presented to management or governance."

The broader Digital Health Strategy, which would have involved substantial investment, was presented to the executive and supported on May 13 and was due to go to the Finance Risk and Audit committee on May 26, the spokesperson said.

"The security strategy work would have informed the Digital Health Strategy as one aspect of that wider programme."

It had not been costed and any associated work programmes not confirmed.

Advertisement
Advertise with NZME.

"This work was interrupted by the cyberattack but has now been restarted."

When asked whether the strategy could have prevented the attack if implemented, the spokesman said elements described in the strategy were under way and in some cases accelerated, such as the migration to the Cloud and organisation-wide adoption of Windows 10.

"...There is no current evidence to indicate whether full implementation of the draft long-term strategy would have impacted the May 18 event."

The spokesman said Windows 10 was deployed on all compatible machines at the time of the cyber-event.

"It is noted that it is not possible in all instances to run Windows 10 due to specific peripheral hardware or medical compliance needs. Mitigations were taken to protect those machines."

The DHB has now recovered from the attack and is continuing to investigate what led to it.

Advertisement
Advertise with NZME.

To date, it has not been said what cost has been incurred by the incident but more than 4200 people were affected and at least 22 people have notified the DHB of a privacy breach.

Complaints have also been lodged with the Privacy Commissioner but a spokesperson would not say how many.

Save

    Share this article

Latest from New Zealand

New Zealand|crime

'I will forever hate you': Victims' torment after 'friend' sexually abused them as boys

15 Jun 08:00 AM
Crime

Coconuts and meth: The story behind NZ's largest pseudoephedrine prosecution

15 Jun 06:00 AM
New Zealand

Police seek witnesses to Rotorua hit-and-run

15 Jun 04:24 AM

It was just a stopover – 18 months later, they call it home

sponsored
Advertisement
Advertise with NZME.

Latest from New Zealand

'I will forever hate you': Victims' torment after 'friend' sexually abused them as boys

'I will forever hate you': Victims' torment after 'friend' sexually abused them as boys

15 Jun 08:00 AM

Glen Wright continues to deny the offending and claims the victims conspired against him.

Coconuts and meth: The story behind NZ's largest pseudoephedrine prosecution

Coconuts and meth: The story behind NZ's largest pseudoephedrine prosecution

15 Jun 06:00 AM
Police seek witnesses to Rotorua hit-and-run

Police seek witnesses to Rotorua hit-and-run

15 Jun 04:24 AM
Afternoon quiz: In which year did New Zealand's currency switch from pounds to dollars?

Afternoon quiz: In which year did New Zealand's currency switch from pounds to dollars?

15 Jun 03:00 AM
The woman behind NZ’s first PAK’nSAVE
sponsored

The woman behind NZ’s first PAK’nSAVE

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP